CVE-2021-40906Medium· 6.1▾ TwilightPoC availableCheckMK Raw Edition software (versions 1.5.0 to 1.6.0) does not sanitise the input of a web service parameter that is in an unauthenticated zone. This Reflected XSS allows an attacker to open a backdoor on the device with HTML content an…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 33.6 · likelihood 0.2 · exploitation 12
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Public exploit / PoC code seen in 1 source. Availability, not in-the-wild use.
Exploit-prediction probability, daily snapshots since Jul 6.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
1.0%
1.0% → 1.0%
1 GitHub repo
CheckMK Raw Edition software (versions 1.5.0 to 1.6.0) does not sanitise the input of a web service parameter that is in an unauthenticated zone. This Reflected XSS allows an attacker to open a backdoor on the device with HTML content and interpreted by the browser (such as JavaScript or other client-side scripts) or to steal the session cookies of a user who has previously authenticated via a man in the middle. Successful exploitation requires access to the web service resource without authentication.
checkmk >= 1.5.0, < 1.6.0checkmk = 1.6.0checkmk = 1.6.0b10checkmk = 1.6.0b11checkmk = 1.6.0p10checkmk = 1.6.0p17checkmk = 1.6.0p18Upgrade past the affected range:
checkmk 1.6.0Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2021-40904High· 8.8The web management console of CheckMK Raw Edition (versions 1.5.0 to 1.6.0) allows a misconfiguration of the web-app Dokuwiki (installed by default), which allows embedded php code
CVE-2021-40905High· 8.8The web management console of CheckMK Enterprise Edition (versions 1.5.0 to 2.0.0p9) does not properly sanitise the uploading of ".mkp" files, which are Extension Packages, making remote code execution possible
CVE-2026-20915Medium· 5.4Stored cross-site scripting (XSS) in Checkmk version 2.5.0 (beta) before 2.5.0b2 allows authenticated users with permission to create pending changes to inject malicious JavaScript into the Pending Changes sidebar, which will execute in …
CVE-2026-33276Medium· 5.4Stored cross-site scripting (XSS) in Checkmk 2.5.0 (beta) before 2.5.0b2 allows authenticated users with permission to create hosts or services to execute arbitrary JavaScript in the browsers of other users performing searches in the Uni…
CVE-2026-90990Medium· 5.3Livestatus injection via monitoring filter values
CVE-2026-92882Low· 2.3Redact SNMP community, SNMPv3 pass phrases, and IPMI password in host config REST API GET responses